I have this current physical setup:
1x RB3011 UiAS-RM Router
1x Cisco SG200-50P Switch (Core Switch)
2x Cisco SG200-50 Switch
The switches were layer 2 and the necessary port trunks have been configured.
Switch 1 (Core):
Port 48 = Router
Port 49 = Switch 2
Port 50 = Switch 3
Problem:
How can I allow all Vlans to access "Vlan100 IT"? This Vlan100 IT is where our biometrics, file server, printer, etc. were connected and I need either every vlans or even just vlan 101, 102, 103, 104, 105, 110 can access to it.
Code: Select all
/interface bridge
add fast-forward=no name=LAN-Bridge
/interface ethernet
set [ find default-name=ether1 ] name=eth1-WAN1
set [ find default-name=ether2 ] name=eth2-WAN2
set [ find default-name=ether5 ] name=eth5-LAN
/interface vlan
add interface=eth5-LAN name="Vlan100 IT" vlan-id=100
add interface=eth5-LAN name="Vlan101 HR/Admin" vlan-id=101
add interface=eth5-LAN name="Vlan102 QA" vlan-id=102
add interface=eth5-LAN name="Vlan103 MC" vlan-id=103
add interface=eth5-LAN name="Vlan104 CS" vlan-id=104
add interface=eth5-LAN name="Vlan105 ConfeRm" vlan-id=105
add interface=eth5-LAN name="Vlan106 GameRm" vlan-id=106
add interface=eth5-LAN name="Vlan110 IT/Admin" vlan-id=110
add interface=eth5-LAN name="Vlan120 WiFi-Admin" vlan-id=120
add interface=eth5-LAN name="Vlan121 WiFi-Staff" vlan-id=121
add interface=eth5-LAN name="Vlan122 WiFi-Guest" vlan-id=122
/ip pool
add name=dhcp_pool1 ranges=10.7.0.51-10.7.255.254
add name=dhcp_pool2 ranges=10.7.1.2-10.7.1.254
add name=dhcp_pool3 ranges=10.7.4.2-10.7.4.254
add name=dhcp_pool4 ranges=10.7.5.2-10.7.5.254
add name=dhcp_pool5 ranges=10.7.6.2-10.7.6.254
add name=dhcp_pool6 ranges=10.7.7.2-10.7.7.254
add name=dhcp_pool7 ranges=10.7.8.2-10.7.8.254
add name=dhcp_pool8 ranges=10.7.9.2-10.7.9.254
add name=dhcp_pool9 ranges=10.7.10.2-10.7.10.254
add name=dhcp_pool10 ranges=10.7.20.2-10.7.20.254
add name=dhcp_pool11 ranges=10.7.21.2-10.7.21.254
add name=dhcp_pool12 ranges=10.7.22.2-10.7.22.254
/ip dhcp-server
add add-arp=yes address-pool=dhcp_pool1 authoritative=after-2sec-delay \
disabled=no interface=LAN-Bridge lease-time=1d name=dhcp1
add address-pool=dhcp_pool2 authoritative=after-2sec-delay disabled=no \
interface="Vlan100 IT" lease-time=1d name=dhcp2
add address-pool=dhcp_pool3 authoritative=after-2sec-delay disabled=no \
interface="Vlan101 HR/Admin" lease-time=1d name=dhcp3
add address-pool=dhcp_pool4 authoritative=after-2sec-delay disabled=no \
interface="Vlan102 QA" lease-time=1d name=dhcp4
add address-pool=dhcp_pool5 authoritative=after-2sec-delay disabled=no \
interface="Vlan103 MC" lease-time=1d name=dhcp5
add address-pool=dhcp_pool6 authoritative=after-2sec-delay disabled=no \
interface="Vlan104 CS" lease-time=1d name=dhcp6
add address-pool=dhcp_pool7 authoritative=after-2sec-delay disabled=no \
interface="Vlan105 ConfeRm" lease-time=1d name=dhcp7
add address-pool=dhcp_pool8 authoritative=after-2sec-delay disabled=no \
interface="Vlan106 GameRm" lease-time=1d name=dhcp8
add address-pool=dhcp_pool9 authoritative=after-2sec-delay disabled=no \
interface="Vlan110 IT/Admin" lease-time=1d name=dhcp9
add address-pool=dhcp_pool10 authoritative=after-2sec-delay disabled=no \
interface="Vlan120 WiFi-Admin" lease-time=1d name=dhcp10
add address-pool=dhcp_pool11 authoritative=after-2sec-delay disabled=no \
interface="Vlan121 WiFi-Staff" lease-time=8h name=dhcp11
add address-pool=dhcp_pool12 authoritative=after-2sec-delay disabled=no \
interface="Vlan122 WiFi-Guest" lease-time=8h name=dhcp12
/interface bridge port
add bridge=LAN-Bridge hw=no interface=eth5-LAN
/ip neighbor discovery-settings
set discover-interface-list=discover
/ip address
add address=10.7.0.1/16 interface=LAN-Bridge network=10.7.0.0
add address=xxx.xxx.xxx.xxx/30 interface=eth1-WAN1 network=xxx.xxx.xxx.xxx
add address=xxx.xxx.xxx.xxx/29 interface=eth2-WAN2 network=xxx.xxx.xxx.xxx
add address=10.7.1.1/24 interface="Vlan100 IT" network=10.7.1.0
add address=10.7.4.1/24 interface="Vlan101 HR/Admin" network=10.7.4.0
add address=10.7.5.1/24 interface="Vlan102 QA" network=10.7.5.0
add address=10.7.6.1/24 interface="Vlan103 MC" network=10.7.6.0
add address=10.7.7.1/24 interface="Vlan104 CS" network=10.7.7.0
add address=10.7.8.1/24 interface="Vlan105 ConfeRm" network=10.7.8.0
add address=10.7.9.1/24 interface="Vlan106 GameRm" network=10.7.9.0
add address=10.7.10.1/24 interface="Vlan110 IT/Admin" network=10.7.10.0
add address=10.7.20.1/24 interface="Vlan120 WiFi-Admin" network=10.7.20.0
add address=10.7.21.1/24 interface="Vlan121 WiFi-Staff" network=10.7.21.0
add address=10.7.22.1/24 interface="Vlan122 WiFi-Guest" network=10.7.22.0
/ip dhcp-server network
add address=10.7.0.0/16 dns-server=10.7.0.1 gateway=10.7.0.1
add address=10.7.1.0/24 dns-server=10.7.1.1 gateway=10.7.1.1
add address=10.7.4.0/24 dns-server=10.7.4.1 gateway=10.7.4.1
add address=10.7.5.0/24 dns-server=10.7.5.1 gateway=10.7.5.1
add address=10.7.6.0/24 dns-server=10.7.6.1 gateway=10.7.6.1
add address=10.7.7.0/24 dns-server=10.7.7.1 gateway=10.7.7.1
add address=10.7.8.0/24 dns-server=10.7.8.1 gateway=10.7.8.1
add address=10.7.9.0/24 dns-server=10.7.9.1 gateway=10.7.9.1
add address=10.7.10.0/24 dns-server=10.7.10.1 gateway=10.7.10.1
add address=10.7.20.0/24 dns-server=10.7.20.1 gateway=10.7.20.1
add address=10.7.21.0/24 dns-server=10.7.21.1 gateway=10.7.21.1
add address=10.7.22.0/24 dns-server=10.7.22.1 gateway=10.7.22.1
/ip firewall nat
add action=masquerade chain=srcnat out-interface=eth1-WAN1
add action=masquerade chain=srcnat out-interface=eth2-WAN2